feat: include Debian source package in get_packages
dpkg-query now also reports ${source:Package} as source_package, so consumers
can match installed binaries to the correct Debian source (e.g. openssh-server
-> openssh) for accurate OSV vulnerability lookups.
This commit is contained in:
@@ -244,7 +244,8 @@ class ProxmoxSystemMixin:
|
|||||||
|
|
||||||
# Installed packages via SSH dpkg-query
|
# Installed packages via SSH dpkg-query
|
||||||
raw = self._exec_ssh_command(
|
raw = self._exec_ssh_command(
|
||||||
"dpkg-query -W -f='${Package}\\t${Version}\\t${db:Status-Status}\\t${Installed-Size}\\n'"
|
"dpkg-query -W -f="
|
||||||
|
"'${Package}\\t${Version}\\t${db:Status-Status}\\t${Installed-Size}\\t${source:Package}\\n'"
|
||||||
" 2>/dev/null"
|
" 2>/dev/null"
|
||||||
)
|
)
|
||||||
result: list[_JsonDict] = []
|
result: list[_JsonDict] = []
|
||||||
@@ -256,6 +257,9 @@ class ProxmoxSystemMixin:
|
|||||||
version = parts[1] if len(parts) > 1 else ""
|
version = parts[1] if len(parts) > 1 else ""
|
||||||
status = parts[2] if len(parts) > 2 else "installed"
|
status = parts[2] if len(parts) > 2 else "installed"
|
||||||
size_kb = parts[3] if len(parts) > 3 else "0"
|
size_kb = parts[3] if len(parts) > 3 else "0"
|
||||||
|
# Debian source package (differs from the binary for split packages,
|
||||||
|
# e.g. openssh-server → openssh). Needed for accurate OSV matching.
|
||||||
|
source_package = parts[4] if len(parts) > 4 and parts[4] else name
|
||||||
if not name or status != "installed":
|
if not name or status != "installed":
|
||||||
continue
|
continue
|
||||||
size_bytes = int(size_kb) * 1024 if size_kb.isdigit() else 0
|
size_bytes = int(size_kb) * 1024 if size_kb.isdigit() else 0
|
||||||
@@ -266,6 +270,7 @@ class ProxmoxSystemMixin:
|
|||||||
"description": "",
|
"description": "",
|
||||||
"size": size_bytes,
|
"size": size_bytes,
|
||||||
"source": "pve",
|
"source": "pve",
|
||||||
|
"source_package": source_package,
|
||||||
"upgrade_version": upgradable.get(name, ""),
|
"upgrade_version": upgradable.get(name, ""),
|
||||||
})
|
})
|
||||||
return result
|
return result
|
||||||
|
|||||||
Reference in New Issue
Block a user